Repository navigation

#

etw-bypass

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

Rust
206
2 个月前

Two in one, patch lifetime powershell console, no more etw and amsi!

Go
88
10 个月前

Generator of https://github.com/TheWover/donut in pure Go. supports compression, AMSI/WLDP/ETW bypass, etc.

Go
53
2 年前

A WIP shellcode loader tool which bypasses AV/EDR, coded in C++, and equipped with a minimal console builder.

C++
44
6 天前

code snippet provided demonstrates how to patch the EtwEventWrite function in the ntdll.dll library on Windows using CGO (C Go).

Go
8
10 个月前

Loads a C# binary in memory within powershell profile, patching AMSI + ETW.

Nim
4
10 个月前

Remove ETW providers from session &ETW session hijack

C++
0
1 个月前